Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 557 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.20% | — | NeuvectorAI | 28/9/2026 | 29/9/2026 | Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise… | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | NeuvectorAI | 17/9/2026 | 28/9/2026 | The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by… | |
| Pendiente de análisis | Baja (2) | 0.19% | — | NeuvectorAI | 17/9/2026 | 28/9/2026 | The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires. | |
| Pendiente de análisis | Alta (7.6) | 0.36% | — | NeuvectorAI | 17/9/2026 | 28/9/2026 | Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to… | |
| Pendiente de análisis | Media (6.8) | 0.20% | — | Suse NeuvectorAI | 9/9/2026 | 10/9/2026 | An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5. | |
| Pendiente de análisis | Alta (7.3) | 0.80% | — | NeuvectorAI | 5/8/2026 | 1/9/2026 | NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information. | |
| Aplazada | Baja (3.8) | 0.09% | — | Neuvector ScannerAI | 25/2/2026 | 17/6/2026 | A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users. | |
| Aplazada | Alta (8.8) | 0.37% | — | NeuvectorAI | 8/1/2026 | 30/9/2026 | NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks. | |
| Aplazada | Media (6.5) | 0.27% | — | NeuvectorAI | 30/10/2025 | 17/6/2026 | NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was replaced with the secret key value and used to encrypt sensitive configurations when NeuVector stores the data. | |
| Aplazada | Alta (8.6) | 0.20% | — | NeuvectorAI | 30/10/2025 | 17/6/2026 | This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends anonymous telemetry data to the telemetry server. In affected versions, NeuVector does not enforce TLS certificate verification when transmitting anonymous… | |
| Aplazada | Crítica (9.9) | 0.47% | — | Neuvector EnforcerAI | 30/10/2025 | 17/6/2026 | A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT to generate a command to be executed via popen, without first sanitising their values. The entry process of the enforcer container is the monitor process. When the enforcer container stops,… | |
| Aplazada | Crítica (9.8) | 0.56% | — | NeuvectorAI | 17/9/2025 | 17/6/2026 | A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an… | |
| Aplazada | Media (5.3) | 0.25% | — | NeuvectorAI | 17/9/2025 | 17/6/2026 | When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log. | |
| Aplazada | Media (5.3) | 0.18% | — | NeuvectorAI | 17/9/2025 | 17/6/2026 | NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are precomputed). | |
| Aplazada | Crítica (9.4) | 0.48% | — | NeuvectorAI | 16/10/2024 | 17/6/2026 | A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE. | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Neuvector Vulnerability Scanner | 29/11/2023 | 17/6/2026 | A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Neuvector Vulnerability ScannerJenkins JiraJenkins Google Compute EngineJenkins Matlab | 29/11/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Media (5.3) | 0.32% | — | Jenkins Neuvector Vulnerability Scanner | 12/4/2023 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server. | |
| Modificada | Media (5.3) | 0.70% | — | Jenkins Neuvector Vulnerability Scanner | 19/10/2022 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download. | |
| Modificada | Crítica (9.8) | 1.4% | — | Neuvector | 20/12/2019 | 17/6/2026 | NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not… | |
| Modificada | Media (5.5) | 0.25% | — | Jenkins Neuvector Vulnerability Scanner | 25/9/2019 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. |